The Naval Surface Warfare Center Philadelphia Division (NSWCPD) is a Department of Defense entity responsible for research and development, test and evaluation, engineering and fleet support organization for the Navy’s ships, submarines, military watercraft and unmanned vehicles. This requirement is for NSWCPD Code 20 Land Based Test Site Programs, which is responsible for the support of Risk Management Framework (RMF) package development of all NSWCPD Land Based Test Sites. All test site systems must receive and maintain full RMF Authority To Operate (ATO) to ensure Cyber Security and Information Assurance (IA) Hardening of all Land Based Test Site Systems. Systems in scope are both Ashore and Afloat systems within each Land Based Test Site.
- Supporting the information system owner to complete security assessments, achieve system authorizations, continuous monitoring, and configuration management
- Verifying patches and virus definitions are updated on the system using existing automated tools
- Adhering to pre-defined configuration management and change management policies for authorizing software prior to its implementation on systems
- Verifying mitigation and closure of open vulnerabilities following the NSWC change control process
- Assessing NSWC systems in accordance with Navy, NIST, DoD, and DISA guidance
- Reporting security incidents in accordance with the Command's Incident Response Plan
- Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices
FILLING THIS POSITION IS CONTINGENT UPON AWARD
#LI-LL1
Requirements- Must possess an active Secret clearance at the minimum
- A minimum of five (5) years of cybersecurity experience
- Must currently hold a DoD 8570-compliant IAT II certification (SSCP or Security+CE with appropriate CE/OS certificate), and IAM II certification (CAP or CASP CE) or be able to obtain within six months; CE/OS certificate may include Windows or Linux
- Experience with eMASS and/or Xacta, ACAS/Nessus, SCAP, Benchmarks, STIG Viewer, and POA&Ms
- Experience with patching, reviewing system and event logs for operating systems such as Windows and Linux
- Must be able to diagnose and solve problems within a computer network
- Have knowledge of National Institute of Science and Technology (NIST) and Defense Information Systems Agency (DISA) standards, guidelines, and requirements as related to Cybersecurity and Risk Management
- Have experience in reviewing compliance in Microsoft Windows, Red Hat Linux and other operating systems in accordance with DISA and NIST requirements
- Five (5) years of professional experience in computer design, software development or computer networks
- Experience in the research, design, development, and test of computer hardware and software programs
- Understanding of the DoD RMF process
- Bachelor's degree in computer, electrical or electronics engineering or mathematics with concentration in computer science
- Minimum current IAT I level certification (A+ CE, CCNA, Security+, Network+ CE, SSCP)
SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL
Travel Requirements- Up to 10% travel may be required
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
EEOScientific Research Corporation is an equal opportunity employer that does not discriminate in employment.
All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.
Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact [email protected] for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
Skills Required
- Active Secret security clearance at minimum
- U.S. citizenship
- At least five years of cybersecurity experience
- Current DoD 8570-compliant IAT II certification, such as SSCP or Security+ CE with appropriate CE/OS certificate, and IAM II certification such as CAP or CASP CE; may obtain within six months
- Experience with eMASS and/or Xacta, ACAS/Nessus, SCAP, benchmarks, STIG Viewer, and POA&Ms
- Experience patching systems and reviewing operating system and event logs
- Ability to diagnose and solve computer network problems
- Knowledge of NIST and DISA cybersecurity and risk management standards
- Experience reviewing Microsoft Windows, Red Hat Linux, and other operating systems for DISA and NIST compliance
- Up to 10% travel
- Five years of professional experience in computer design, software development, or computer networks
- Experience researching, designing, developing, and testing computer hardware and software
- Understanding of the DoD Risk Management Framework process
- Bachelor's degree in computer, electrical, or electronics engineering, or mathematics with a concentration in computer science
- Current IAT I certification, such as A+ CE, CCNA, Security+, Network+ CE, or SSCP
What We Do
Sciolex Corporation is a CVE-certified Service-Disabled Veteran-Owned Small Business that provides systems and mission engineering, technical assistance, operations advisory, cloud computing, acquisition support, and executive and administrative services. The company supports federal civil, defense, and Intelligence Community agencies, helping them plan, integrate, test, deploy, and manage information, technology, and mission capabilities while improving information operations through research and innovative processes.








